KlarComply
German version (binding) Nederlands

Data Processing Agreement

pursuant to Art. 28 Regulation (EU) 2016/679 (GDPR) · version 1.0 · as of July 2026
English translation for information purposes. Legally binding is the German version 1.0 published at klarcomply.com/avv, which is accepted electronically when the company account is created.
Controller (“Customer”)
[Company name — added when the subscription is taken out]
represented by the authorised signatory
Processor (“KlarComply”)
Patrick de Kathen (sole trader)
10 Xagħra Heights, Xagħra, Gozo, Malta (EU)
kontakt@klarcomply.com

1. Subject matter and duration

KlarComply provides the Customer with the services described in the subscription agreement (compliance dashboard, online training, evidence management under Regulation (EU) 2024/1689). In doing so, KlarComply processes personal data on behalf of the Customer. This agreement applies for the duration of the subscription and ends upon its termination; clause 7 (deletion) remains unaffected.

2. Nature, purpose and scope of processing

Storage, organisation and evaluation of data of the Customer's employees for the purposes of training management, certificate management, evidence management (AI inventory, policy details, acknowledgment logs) and access management. Details: Annex 1.

3. Right of instruction

KlarComply processes the data exclusively on the Customer's documented instructions (Art. 28(3)(a) GDPR); the Customer's use of the platform features constitutes an instruction. If KlarComply considers an instruction unlawful, it shall inform the Customer without undue delay and may suspend execution.

4. Confidentiality and security

  1. Persons authorised to process the data are committed to confidentiality (Art. 28(3)(b)).
  2. KlarComply implements the technical and organisational measures set out in Annex 2 (Art. 32 GDPR) and adapts them to the state of the art without lowering the level of protection.

5. Sub-processors

The Customer grants general authorisation for the use of the sub-processors listed in Annex 3. KlarComply gives notice of intended changes; the Customer may object within 14 days on substantial data-protection grounds. Agreements pursuant to Art. 28 GDPR are in place with all sub-processors.

6. Duties of assistance

KlarComply assists the Customer, to the extent reasonable, in responding to data-subject requests (Art. 12–23), in securing the processing, in data protection impact assessments and in notification duties (Art. 32–36). KlarComply notifies the Customer of personal data breaches without undue delay.

7. Deletion and return

After termination of the subscription, KlarComply deletes all personal data processed on behalf of the Customer within 30 days, unless a statutory retention duty applies. The Customer may back up its data beforehand via the dashboard's export/print functions. Issued certificates remain stored for public verification (legitimate interest of the certificate holders); the Customer may request their deletion.

8. Evidence and audits

KlarComply provides the Customer with the information necessary to demonstrate compliance with the obligations under Art. 28 GDPR and enables audits — upon notice and at most once per year, except where there is specific cause. Evidence may be provided through current attestations/certifications of the sub-processors (e.g. SOC 2, ISO 27001).

9. Third-country transfers

Processing takes place in data centres in the EU (Frankfurt region, Germany). Where sub-processors established outside the EU are used (Annex 3), any transfer is based on EU standard contractual clauses or an adequacy decision (e.g. the EU-US Data Privacy Framework).

10. Final provisions

The law applicable to the subscription agreement also applies here. In case of conflict, this agreement prevails in data-protection matters. Should any provision be invalid, the remaining provisions remain in force.

Annex 1 — Data and data subjects

Data subjectsEmployees, contact persons and, where applicable, external staff of the Customer
Data categoriesName, business email address, role; training progress and results (per cent); certificate data (name, company, date, check-ID); acknowledgment logs (who, what, when); details maintained by the Customer (AI inventory, contact person, rules)
No processing ofspecial categories under Art. 9 GDPR; such data must not be entered into the platform

Annex 2 — Technical and organisational measures (Art. 32)

Annex 3 — Sub-processors

ProviderPurposeRegistered office / region
Supabase Inc.Database, authentication, server functionsUSA · data stored in the EU (AWS Frankfurt) · SCC/DPF
Cloudflare Inc.Website hosting, CDN, securityUSA · EU delivery · SCC/DPF
MailerLite (UAB)Newsletter/notifications (contact email only)Lithuania (EU)

Note: payment data is processed by Stripe Payments Europe Ltd. as an independent controller — it is not covered by this data processing agreement.

Acceptance

This agreement is concluded electronically (Art. 28(9) GDPR). Acceptance takes place in the KlarComply dashboard by the Customer's authorised signatory; time, name and contract version are logged verifiably. The binding text is the German version 1.0 (see klarcomply.com/avv).

KlarComply · klarcomply.com · This document forms part of the subscription agreement. · Back to homepage